天下漏洞,尽知其名
MEDIUM 重点关注

CVE-2026-92103 elixir-mint 资源无限制分配漏洞

影响恶意HTTP/2服务器可耗尽客户端内存,导致拒绝服务

MEDIUM
暂无 CVSS 评分
AI 研判

CVE-2026-92103 是 elixir-mint 库中 Mint.HTTP2.Frame.decode_next/2 的资源分配不受限漏洞。恶意 HTTP/2 服务器可声明超大帧长度并故意不发送最后一个字节,使客户端持续缓存数据,每个连接最多占用约 16 MiB 内存。

影响范围

elixir-mint mint

影响 mint 库 0.1.0 至 1.11.0 之前的版本。

漏洞详情

该漏洞属于资源分配无限制/无节流类型。Mint 在解码 HTTP/2 帧时,只有等整个声明的负载全部到达后才与客户端的 max_frame_size(默认 16,384 字节)比较,在此之前一直返回 :more 并把收到的每个字节保留在连接缓冲区中。服务器可声明最大 16,777,215 字节的帧长度并扣留最后一个字节,从而让客户端缓存约 1,024 倍于限制的数据。

利用条件与风险

利用前提是客户端连接恶意 HTTP/2 服务器;服务器需实际发送客户端缓存的每个字节,因此无放大效应,但可长期占用内存造成拒绝服务。

修复建议

升级 mint 至 1.11.0 或更高版本;暂无公开的临时缓解措施信息。

原始情报

Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint mint allows a malicious HTTP/2 server to make the client hold up to about 16 MiB per connection in frames it should reject, consuming client memory.

Mint.HTTP2.Frame.decode_next/2 in lib/mint/http2/frame.ex compares a frame with the client’s max_frame_size (16,384 bytes by default) only once the whole declared payload has arrived. Until then it returns :more, and Mint.HTTP2 keeps every received byte in the connection buffer. A server can declare a frame length of up to 16,777,215 bytes and withhold the last byte, keeping roughly 1,024 times the advertised limit buffered for as long as the connection stays open. The server has to send every byte the client buffers, so there is no amplification, and the buffer stops at the 24-bit frame length limit.

This issue affects mint: from 0.1.0 before 1.11.0.